MEDIUMnpm

Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint

Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint

CVE-2023-46729Published 2 years agoUpdated 5 days agoSource: OSV

Affected packages

  • @sentry/nextjs

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint | HackTribune